Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.

Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a Windows Hello for Business key from a compromised user session without a fresh PIN or biometric check. None cracked the math.

The impact is not the same in all three cases.

SpecterOps showed a Windows and Microsoft Entra ID chain that could impersonate privileged users while satisfying phishing-resistant multifactor authentication (MFA); that chain reused signed authentication material rather than stealing the authenticator's private key.

Unit 42 showed attacks against Google Password Manager in Chrome, including a path that recovers the private keys for a victim's synced passkeys.